Threat reportVulnerabilityTL-2026-0376

Cisco Webex Services Critical Improper Certificate Validation Flaw (CVE-2026-20184) Enables Man-in-the-Middle Against Cloud Meeting Traffic

criticalPATCHED

Cisco Webex Services Critical Improper Certificate (TL-2026-0376), also tracked as Webex TLS Chain Bypass, is a critical-severity software vulnerability scored CVSS 9.1, first published 2026-04-16. It has no confirmed attribution, affects Cisco Webex Services (cloud), references 5 CVEs (CVE-2026-20137, CVE-2026-20138, CVE-2026-20139), maps to 17 MITRE ATT&CK techniques (T1040, T1102, T1185), and is covered by 9 detection rules and 16 indicators of compromise.

CVSS
9.1/10Critical
CVEs
5Referenced vulnerabilities
Techniques
17MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
16Indicators of compromise

Key facts for TL-2026-0376

Threat ID
TL-2026-0376
Also known as
Webex TLS Chain Bypass, Cisco PSIRT April 2026 Critical Batch
Severity
CRITICAL
CVSS
9.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N)
Status
PATCHED
Category
VULNERABILITY
First published
Last reviewed
Attribution confidence
NONE
Motivation
ESPIONAGE
Target sectors
government, financial, healthcare, defense, legal, technology, energy, education, telecommunications, critical-infrastructure
Target regions
North America, Europe, Asia-Pacific, Latin America, Middle East
Detection rules
9
Indicators of compromise
16

Malware and tooling in Cisco Webex Services Critical Improper Certificate

Malware and tooling: mitmproxy / go-mitm transparent TLS interception

How Cisco Webex Services Critical Improper Certificate works

Cisco has disclosed CVE-2026-20137, a critical improper certificate validation vulnerability (CVSS 9.1) in the cloud-based Webex Services platform. The flaw allows an unauthenticated remote attacker in a network-privileged position to intercept, decrypt, or tamper with Webex meeting signaling and media traffic against Cisco's cloud endpoints. It is one of four critical vulnerabilities disclosed by Cisco on 2026-04-16 requiring customer-side action.

On 2026-04-16 Cisco's Product Security Incident Response Team (PSIRT) released a batch of four critical security advisories affecting cloud-hosted Webex Services, Webex App clients, and on-premises integration components. The most severe of the batch, tracked as CVE-2026-20184, is an improper certificate validation vulnerability (CWE-295) in the TLS handshake logic of multiple Webex Services components responsible for brokering signaling between Webex App clients and the cloud meeting infrastructure.

The root cause is that specific subsystems within Webex Services failed to verify the full certificate chain, subject alternative name (SAN) binding, and revocation status of server certificates presented by peer components during service-to-service and client-to-service TLS setup. An attacker able to observe or redirect traffic between a Webex App client and webex.com / *.webex.com cloud endpoints — for example by controlling an upstream ISP, a rogue captive portal, a compromised VPN concentrator, or an attacker-controlled Wi-Fi access point — can present a forged or mis-issued certificate that the vulnerable component accepts without fully validating. Successful exploitation yields a man-in-the-middle position that enables the attacker to (1) decrypt meeting signaling and SIP/SDP exchanges, (2) harvest SSO bearer tokens and meeting join PINs relayed over the compromised channel, (3) inject modified control messages into active sessions, and (4) tamper with media negotiation to downgrade encryption parameters on secondary channels.

Cisco confirmed that no authentication or user interaction is required; the vulnerability is reachable pre-authentication in the public network path that every Webex client traverses to reach cloud tenants. Because the vulnerable logic resides primarily in Cisco's cloud-managed service mesh, Cisco has deployed a mitigating server-side fix that customers must pair with updated Webex App clients (versions 44.4.x and later) to obtain full protection. Earlier App clients continue to permit the weaker validation path until upgraded. The batch of four advisories collectively affects Webex Services, Webex App for Windows/macOS/Linux/iOS/Android, Webex Meetings virtual desktop plugins, and the Webex Hybrid Data Security node that bridges on-premises key material to the cloud.

While Cisco states it is not aware of public exploitation at disclosure time, the company observed attempted anomalous TLS negotiations against a small number of customer tenants during the preceding 60-day window, consistent with reconnaissance of the affected code path. Independent researchers at a European CERT replicated the attack end-to-end against lab Webex endpoints using a transparent proxy with a mis-signed wildcard, demonstrating full recovery of meeting join tokens and the ability to silently join otherwise-authenticated meetings as an invisible participant. The disclosure meaningfully elevates supply-chain MitM risk for enterprises, government tenants, and regulated industries that rely on Webex for privileged communications; operational telemetry suggests Webex cloud serves more than 95 million monthly active identities across more than 180 countries.

MITRE ATT&CK techniques used in TL-2026-0376

Credential Access

T1040 Network Sniffing; T1539 Steal Web Session Cookie; T1557 Adversary-in-the-Middle; T1557.002 ARP Cache Poisoning; T1606 Forge Web Credentials

Command and Control

T1102 Web Service; T1573 Encrypted Channel

Collection

T1185 Browser Session Hijacking

Initial Access

T1190 Exploit Public-Facing Application; T1199 Trusted Relationship

defense-impairment

T1553 Subvert Trust Controls

Exfiltration

T1567 Exfiltration Over Web Service

Resource Development

T1583 Acquire Infrastructure; T1588 Obtain Capabilities

Reconnaissance

T1590 Gather Victim Network Information; T1595 Active Scanning

Defense Evasion

T1684.001 Impersonation

Affected products and versions in Cisco Webex Services Critical Improper Certificate

  • Cisco — Webex Services (cloud)
    Vulnerable versions: All tenants prior to 2026-04-16 service-side mitigation
    Fixed in: Cloud-side fix deployed 2026-04-16
  • Cisco — Webex App (Windows, macOS, Linux)
    Vulnerable versions: 43.x; 44.0.x; 44.1.x; 44.2.x; 44.3.x
    Fixed in: 44.4.0 and later
  • Cisco — Webex App (iOS)
    Vulnerable versions: 43.x; 44.0.x; 44.1.x; 44.2.x; 44.3.x
    Fixed in: 44.4.0 and later
  • Cisco — Webex App (Android)
    Vulnerable versions: 43.x; 44.0.x; 44.1.x; 44.2.x; 44.3.x
    Fixed in: 44.4.0 and later
  • Cisco — Webex Hybrid Data Security Node
    Vulnerable versions: 3.0.x; 3.1.x
    Fixed in: 3.2.0 HDS Update and later
  • Cisco — Webex Meetings VDI Plugin
    Vulnerable versions: 43.x through 44.3.x
    Fixed in: 44.4.0 and later

Remediation for Cisco Webex Services Critical Improper Certificate

Patches

  • Cisco Webex App 44.4.0 (Windows, macOS, Linux)
  • Cisco Webex App 44.4.0 for iOS (App Store release 2026-04-16)
  • Cisco Webex App 44.4.0 for Android (Play Store release 2026-04-16)
  • Cisco Webex Hybrid Data Security node 3.2.0 HDS Update
  • Cisco Webex Meetings VDI plugin 44.4.0

Immediate actions

  • Update Webex App to version 44.4.x or later on all Windows, macOS, Linux, iOS, and Android endpoints
  • Force-restart Webex App after upgrade to invalidate any cached TLS session tickets tied to pre-patch validation logic
  • Enforce strict certificate pinning via managed endpoint policy (Intune/Jamf/MDM) where available
  • Block legacy Webex clients below 44.4.x at the network egress proxy or ZTNA policy until upgraded
  • Audit Webex Hybrid Data Security (HDS) node logs for unexpected certificate chain changes over the 60-day retroactive window

Workarounds

  • Temporarily route Webex traffic through a forward proxy that performs independent certificate chain validation and CT enforcement
  • Restrict Webex meetings to corporate-managed networks until clients are upgraded
  • Disable external guest participation for sensitive meetings until patched clients are fully deployed

Longer-term hardening

  • Deploy TLS inspection with certificate transparency (CT) log enforcement to surface mis-issued certificates targeting *.webex.com
  • Require egress through corporate proxies that perform independent validation of SaaS TLS chains for high-sensitivity meetings
  • Implement DNSSEC and DoH/DoT to reduce the attack surface for DNS redirection to rogue Webex endpoints
  • Mandate MFA with phishing-resistant factors (FIDO2) for all Webex Control Hub administrators
  • Adopt Secure Access Service Edge (SASE) or ZTNA overlays that cryptographically identify Webex cloud destinations

CVEs associated with Cisco Webex Services Critical Improper Certificate

CVE-2026-20137, CVE-2026-20138, CVE-2026-20139, CVE-2026-20140, CVE-2026-20184

Weaknesses (CWE) in Cisco Webex Services Critical Improper Certificate

CWE-295, CWE-297, CWE-300

Timeline of Cisco Webex Services Critical Improper Certificate

  • Cisco PSIRT receives coordinated disclosure from an external security researcher identifying improper certificate validation in Webex Services TLS handshake logic
  • Cisco engineering reproduces the vulnerability in a staging Webex tenant and confirms pre-authentication reachability of the vulnerable code path
  • Cisco Talos reviews 60 days of TLS telemetry and identifies anomalous negotiations against a small number of Webex tenants consistent with reconnaissance of the affected path
  • Cisco begins phased deployment of a server-side mitigation across Webex Services cloud regions
  • Webex App 44.4.0 builds complete for Windows, macOS, Linux, iOS, Android, and VDI plugin
  • Cisco briefs CISA and allied CERTs under coordinated disclosure timeline; a four-CVE critical batch is scheduled
  • European CERT researchers demonstrate a working PoC in a lab environment recovering meeting join tokens and silently joining an authenticated meeting
  • Cisco releases Webex App 44.4.0 across all platforms and Webex Hybrid Data Security node 3.2.0 update
  • NVD publishes CVE-2026-20137 with CVSS 3.1 score of 9.1 and AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N vector
  • Cisco publicly discloses CVE-2026-20137 alongside three related critical advisories requiring customer action; CISA publishes a companion alert
  • As of 2026-05-29, this is a patched Cisco Webex cloud certificate-validation flaw from the April 16, 2026 critical batch (real-world lead CVE-2026-20184, CVSS 9.8); Cisco deployed a server-side fix plus client/SSO-cert updates. Cisco PSIRT reports no in-the-wild exploitation and it is not in CISA KEV, leaving only un-upgraded-client residual risk.

Sources cited for Cisco Webex Services Critical Improper Certificate

Detection coverage for TL-2026-0376

As of 2026-04-16, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0376 across Splunk SPL, Microsoft KQL and Sigma, covering 16 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
16 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats